Qilin, historically known as Agenda and also tracked as Water Galura, is a Russian-speaking ransomware-as-a-service operation active since 2022. The operation supplies customizable ransomware to affiliates and uses double-extortion tactics, encrypting victim data while using purportedly stolen data to pressure organizations into payment through a leak site. Qilin has used Go- and Rust-based lockers, including variants for Windows, Linux, and VMware ESXi environments. Its Windows payloads have been customized per victim and can terminate security, backup, database, virtualization, and business-application processes and services; delete shadow copies; encrypt files using hybrid cryptography; and leave ransom instructions. Rust variants support intermittent encryption to accelerate impact and complicate detection. Documented affiliate tradecraft includes phishing and fake CAPTCHA lures, use of valid or stolen credentials and tokens, exploitation of public-facing systems, remote-management-tool abuse, network reconnaissance, lateral movement, credential theft from backup infrastructure, and ransomware deployment through enterprise administration mechanisms. Qilin affiliates have also used BYOVD, DLL sideloading, process injection, UAC-related bypass techniques, and security-control impairment. Victimization has spanned multiple regions and sectors, with recurring targeting of manufacturing, construction, professional services, healthcare, education, technology, and financial services organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability, tracked as CVE-2026-50751 (CVSS: 9.3) is a logic flow weakness within Remote Access and Mobile Access certificate validation in the deprecated IKEv1 key exchange, which can allow an unauthenticated attacker to bypass user authentication and establish a VPN connection without a valid password. | One of the observed attacks was linked to a Qilin ransomware affiliate.
References: Exploitation of CVE-2026-0257 Leads to Qilin Ransomware – Arctic Wolf. | Qilin remained the most active ransomware brand targeting industrial organizations, a position it has held since March 2025.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
Recently, the group have been observed exploiting CVE-2025-31324, (SAP NetWeaver Visual Composer vulnerability) and have previously exploited CVE-2023-27532 (Veeam Backup and Replication vulnerability). | Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. CVE-2024–21762, patched in February 2025, remains a major concern with tens of thousands of exposed systems. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | Qilin ransomware, also known as Agenda, has emerged as one of the most significant and evolving cyber threats globally, rapidly ascending to become a top-tier ransomware-as-a-service (RaaS) operation.
On June 8th 2026, Check Point Research identified two CVEs (CVE-2026-50751, CVE-2026-50752) which can be abused to bypass Checkpoint VPN Authentication services, allowing threat actors to access network devices and traffic behind the VPN. | Check Point Research has medium confidence that the attacker is affiliated with Qilin as they use the Qilin ransomware toolkit.
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Qilin ransomware-as-a-service (RaaS) group, also tracked as Water Galura and historically known as Agenda, since its emergence in 2022.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
In recent months, the Lazarus Group and its related intrusion set Moonstone Sleet have also been attributed to attacks targeting South Korean and Middle East entities with Qilin and Medusa ransomware.
Public reporting indicates that the operators were likely active months earlier as an affiliate (known as ArmCorp) of Qilin RaaS, which Unit 42 tracks as Spikey Scorpius.
Qilin is a financially-motivated cybercriminal group first observed in the beginning of July 2022 as Agenda ransomware. The group rebranded as Qilin in September of the same year and have operated as a Ransomware-as-a-service (‘RaaS’) since February 2023.
According to VX-Underground, DragonForce proposed establishing communication channels with the LockBit and the Qilin group.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
We believe that the threat actor used a valid account to access this server and later move inside the victim’s network. This was expected since the actor configured the ransomware with valid and privileged accounts. The threat actor used RDP on Active Directory using leaked accounts.
Next, the scheduled task was pushed by the group policy domain machine.
We believe that the threat actor used a valid account to access this server and later move inside the victim’s network. This was expected since the actor configured the ransomware with valid and privileged accounts. The threat actor used RDP on Active Directory using leaked accounts.
Agenda proceeds to create the runonce autostart entry ... HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ... It then proceeds to configure the Winlogon registry entry ... Agenda changing the registry value of EnableLinkedConnection to 1
Agenda proceeds to create the runonce autostart entry *aster pointing to enc.exe, which is a dropped copy of itself under the Public folder
Next, the scheduled task was pushed by the group policy domain machine.
Agenda injects this DLL into svchost.exe to allow continuous execution of the ransomware binary.
We believe that the threat actor used a valid account to access this server and later move inside the victim’s network. This was expected since the actor configured the ransomware with valid and privileged accounts. The threat actor used RDP on Active Directory using leaked accounts.
Agenda begins the user impersonation ... attempt logging a user on to the local computer via the API LogonUserW. Agenda then proceeds ... execution of the ransomware binary through the API CreateProcessAsUserW
The threat actor seemed to have scanned the network on the first day, and then a Group Policy Object (GPO) was created and the ransomware was deployed on the machines.
Agenda proceeds to create the runonce autostart entry *aster pointing to enc.exe, which is a dropped copy of itself under the Public folder
It then proceeds to configure the Winlogon registry entry, setting the data to each of these values: ... AutoAdminLogon value =1 DefaultUserName = {username} DefaultDomainName ={domainname} DefaultPassword={ Y25VsIgRDr}
The Agenda ransomware is also known to deploy customized ransomware for each victim, and we have seen that its Rust variants have an allocated space for adding accounts in their configuration to be used mostly for privilege escalation.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
Agenda injects this DLL into svchost.exe to allow continuous execution of the ransomware binary.
The ransomware then removes shadow volume copies via execution of vssadmin.exe delete shadows /all /quiet
We believe that the threat actor used a valid account to access this server and later move inside the victim’s network. This was expected since the actor configured the ransomware with valid and privileged accounts. The threat actor used RDP on Active Directory using leaked accounts.
Agenda proceeds to create the runonce autostart entry ... HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce ... It then proceeds to configure the Winlogon registry entry ... Agenda changing the registry value of EnableLinkedConnection to 1
“Allied Recycling … has fallen victim to a ransomware attack conducted by the group qilin.”
The ransomware then removes shadow volume copies ... as well as terminating specific processes and services indicated in its runtime configuration, some of which are antivirus-related processes and services.
The ransomware then removes shadow volume copies via execution of vssadmin.exe delete shadows /all /quiet
289 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-Service operation that maintains a dark-web leak portal and claimed responsibility for compromising an isolated ATF system. It was first identified as Agenda in August 2022.
A double-extortion ransomware-as-a-service operation providing customizable Go-based and later Rust-based ransomware builds to affiliates. Its variants target Windows, Linux, and ESXi environments; affiliates also use lateral-movement tooling, loaders, and BYOVD defense-evasion techniques.
Named as one of the five most common ransomware-as-a-service brands in Sophos's ransomware observations.
A Russian-speaking RaaS operation whose affiliates are described as commonly using phishing, compromised VPN/RDP credentials, and exploitation of public-facing applications for initial access. It allegedly listed ATF on its leak site, but the claim was unsubstantiated and ATF/DOJ had not attributed the incident to Qilin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.